Dear reader, first of all, I would like to point out that as a resident of Germany, I primarily describe the situation in this country. Perhaps the situation in your country is radically different.
On December 17, 2019, information about a critical vulnerability in the Citrix Application Delivery Controller (NetScaler ADC) and Citrix Gateway products, commonly known as NetScaler Gateway, was published on the Citrix Knowledge Center page. Subsequently, the vulnerability was also found in the SD-WAN line. The vulnerability affected all product versions, from 10.5 to the current 13.0, allowing an unauthorized attacker to execute malicious code in the system, effectively turning NetScaler into a platform for further attacks on the internal network.
Simultaneously with the release of information about the vulnerability, Citrix published recommendations for risk mitigation (Workaround). Full closure of the vulnerability was only promised by the end of January 2020.
The criticality of this vulnerability (CVE-2019-19781) was . According to the vulnerability affects over 80,000 companies worldwide.
Possible response to the news
As a responsible person, I believed that all IT specialists with NetScaler products in their infrastructure acted as follows:
- immediately implemented all the recommendations outlined in article CTX267679 for risk minimization.
- rechecked the Firewall settings regarding allowed traffic from NetScaler to the internal network.
- recommended that IT security administrators pay attention to "unusual" access attempts to NetScaler and, if necessary, block them. I remind you, NetScaler is usually located in the DMZ.
- assessed the possibility of temporarily disconnecting NetScaler from the network until more detailed information about the issue was obtained. During pre-Christmas vacations, holidays, etc., this would be less painful. Additionally, many companies have alternative access through VPN.
What happened next?
Unfortunately, as will become clear later, the aforementioned steps, which are standard practice, were largely ignored by most.
Many professionals responsible for the Citrix infrastructure only learned about the vulnerability on 01/13/2020 . They found out at a time when a large number of the systems under their care had been compromised. The absurdity of the situation reached a point where the necessary exploits could be easily .
For some reason, I thought that IT specialists read newsletters from the manufacturers of the systems entrusted to them, knew how to use Twitter, followed leading experts in their field, and were required to stay informed about current events.
In fact, for more than three weeks, numerous Citrix clients completely ignored the manufacturer's recommendations. Citrix clients include nearly all large and medium-sized companies in Germany, as well as almost all government institutions. Primarily, the vulnerability affected government structures.
At least there's something to do
Those whose systems were compromised need to fully reinstall them, including replacing TLS certificates. It is possible that Citrix clients expecting more proactive actions from the manufacturer to address this critical vulnerability will seriously look for alternatives. It must be acknowledged that Citrix's response does not inspire optimism.
There are more questions than answers
The question arises, what have the numerous partners of Citrix, both platinum and gold, been doing? Why did necessary information only appear on the pages of some Citrix partners in the third week of 2020? It is obvious that even the highly paid external consultants also slept through this dangerous situation. I don't want to offend anyone, but a partner's primary task is to prevent emerging problems, not to offer = sell assistance in resolving them.
In fact, this situation has revealed the real state of affairs in IT security. Both IT department employees and consultants from Citrix partner firms should understand one truth: if there is a vulnerability, it must be addressed. And a critical vulnerability must be addressed immediately!
Source: habr.com
